Security Cryptography Whatever cover image

Threema with Kenny Paterson, Matteo Scarlata and Kien Tuong Truong

Security Cryptography Whatever

00:00

ATT&CK2 Attack

ATT&CK2 is able to register the servers' public key as a user's public key by tricking the victim into sending a carefully crafted message in the ETE protocol and enables it to permanently impersonate the victim. This is a fun cross-particle attack between the C2S, aka the TLS-like client to server protocol and the actual end-to-end encrypted messaging protocol underneath it. The idea is that whenever you receive a message, if there is a metadata box, the values contained within the metadata box will overwrite the values outside.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app